19 ms·
ChatControl: EU wants to scan all private messages, even in encrypted apps
- bikemike026 1y agoAre the Europeans insane? The modern world is becoming a horror. I think I would rather live in a dark forest. Life is becoming pointless.
- topspin 1y ago> Are the Europeans insane? I don't think so. If they were, it would actually be better: one can have sympathy for insanity, and at least isolate it, if not treat it. Instead, it's extreme insecurity combined with limitless regard for infallible authority. The thought that the hoi polloi might write or say things that are beyond scrutiny is intolerable. That's the insecurity part. And all intolerable things must be criminalized, because in Europe, laws infallibly fix everything. That's the authority part. That's not insanity. That's just how you behave when you imagine it is your mandate to perfect the world and indulge hubris sufficient to believe you have the wisdom to do so.
- immibis 1y agoThis will never not be in the news, will it? I feel like it's been continuously for the past 10-15 years, under various names.
- jjice 1y agoJust need to pass it once, unfortunately. And despite all the talk against it, they get a partial fresh start to the general public every time one of these is proposed.
- dekken_ 1y agoThe IRA quote to Thatcher comes to mind
- bigyabai 1y agoHonestly, I fully expect that the scanning method is already implemented and used. The US has intervened with some pretty deep surveillance in the past (ie. Canada Sihk killing) and doesn't seem to need permission to get it. Sounds to me like the EU is looking to get a more formal approval to act on data they already have.
- EasyMark 1y agoThe people that want this to happen, really really really want it to happen. They are never going to give up, so people need to remain vigilent.
- haolez 1y agoI think the challenge for society here is not to simply reject attempts like this, but how to prevent them from being pushed over and over until a specific context allows it to be approved.
- thinkingtoilet 1y agoAgreed. In this case, there needs to be some sort of 'privacy bill of rights'. Something fundamental where any law like this cannot be passed.
- quotemstr 1y agoLaws don't stop men with guns. Men with guns stop men with guns. Laws not enforced and rights not protected don't matter. As the old saying goes, the price of freedom is eternal vigilance.
- mapontosevenths 1y ago> Laws don't stop men with guns. Men with guns stop men with guns. Prove it. Every statistic I've ever seen shows the exact opposite of this to be true.
- logicchains 1y agoHere's the proof: https://en.wikipedia.org/wiki/Mass_killings_under_communist_regimes https://en.wikipedia.org/wiki/Mass_killings_under_communist_... . Those kinds of mass killings can only happen when the citizens are disarmed, because it's logistically impossible for a government to seize absolute power when a significant proportion of the citizens are armed.
- 1718627440 1y agoThose kind of mass killings also happen in authoritative regimes, which typically emerge from violent societies.
- daemin 1y agoI was just thinking that if something like this ever does get through and become law, then creating open-source alternatives which do not obey these laws would be quite trivial. What would not be trivial would be deciding where to host the servers and source code, and how to actually get this software onto people's devices. What country would be safe for hosting code that does this that people would also trust in general? Would this be hosted on the dark web or would someone actually be brave enough to host it on their private machines? Would there be DNS that could point to this? Then how would you install the software? You'd need a way to side-load it, which means you'd want a way to sign it. Which means either adding a new root signing authority or being able to have an existing root authority sell you a signing certificate and not revoke it. You kind of quickly end up in some weird dystopian cyberpunk setting thinking all of this through.
- bigyabai 1y ago> You kind of quickly end up in some weird dystopian cyberpunk setting thinking all of this through. The most dystopian concept out of everything you mentioned is still "you can't install unsigned software" to me.
- simonw 1y agoGood luck preventing people from loading up a web page that runs a pure JavaScript (or WebAssembly) implementation of common cryptography algorithms and lets people copy and paste each other encrypted messages.
- roywiggins 1y agoChat Control wants to require on-device scanning, so if this becomes common they can move to mandating scanning at the OS or browser level as well.
- __loam 1y agoGood luck convincing American tech to take on a liability like this. There's a reason big tech is moving to e2e encryption like Signal and it isn't user privacy. Telling governments to fuck off because you don't have the data limits liability.
- dcanelhas 1y agoI wonder where platforms like slack would land in all of this, and how would they go about akeeping people from just using their own encryption e.g. pgp over unencrypted channels? Is public key cryptography too weak to matter?
- naijaboiler 1y agoThis legislation makes every digital communication open to being policed at the source. It is far too overreaching and too rife for abuse.
- palata 1y agoSlack is not end-to-end encrypted and belongs to a US company. So there is no need for ChatControl there: the US government already has access to everything that is written on Slack.
- Bender 1y agoI believe they are referring to using GPG to encrypt data before putting it into Slack, much like using the out of band OTR. In that case all the data shared between those using GPG or OTR would only be accessible to those with the right out of band keys. There are probably not a lot of people doing this, or not enough for governments to care. I do this in IRC using irssi-otr [1]. If that ever became illegal because encryption then groups of people could simply use scripts or addons to pipe through different types of encoding to make AI fuzzy searches harder. They can try to detect these chains of encoding but it will be CPU expensive to do every combination at scale given there are literally thousands of forms of encoding that could be chained in any order and number. Mon -> base64 -> base2048 [2] Tue -> base2048 -> base131072 [3] ...and so on. [1] - https://irssi.org/documentation/help/otr/ https://irssi.org/documentation/help/otr/ [2] - https://github.com/qntm/base2048 https://github.com/qntm/base2048 [3] - https://github.com/qntm/base131072 https://github.com/qntm/base131072
- palata 1y ago> I believe they are referring to using GPG to encrypt data before putting it into Slack In good approximation, nobody does that. And anyone who is capable of communicating over PGP won't be covered by ChatControl anyway. They can keep using PGP over whatever they want, or just compile Signal from sources. > If that ever became illegal because encryption then groups of people could simply use scripts or addons to pipe through different types of encoding to make AI fuzzy searches harder. I don't think that this makes any sense at all. This is some kind of poor encryption. Either you honour the law and you send your messages in plaintext, or you don't and you use proper encryption. There is nothing worth anything in-between. If encryption is illegal, those who really need it can still use steganography.
- astroflection 1y agoGovernments should be transparent and the people should be opaque. Any government that attempts to make things otherwise looses legitimacy.
- quotemstr 1y agoOr as someone put it, "People shouldn't fear the government. The government should fear the people." I feel like we've lost the vocabulary we ought to be using to talk about the legitimacy and role of the state. More people need to read J.S. Mill (and probably Hobbes.) Even today, works by both are surprisingly good reads and embed a lot of thoughtful and timeless wisdom.
- tremon 1y agoBut isn't the government fearing the people exactly why they're relentlessly pushing ChatControl?
- EasyMark 1y ago> Governments should be transparent and the people should be opaque. I'm going to add this to my repertoire since it's a lot more concise than most of my rantings on the topic
- ivape 1y agoCan anyone try to explain to be how this is not a strain of mind-reading and thought crime? I mean, sure, we’re several decades away from the big event where society will adjudicate thought-crime, but this appears to be one of the first skirmishes.
- brap 1y agoThought crime has been illegal in the EU/UK for quite some time. But only a certain kind of thoughts
- lioeters 1y agoThoughtControl 2030: EU wants to scan all private thoughts and communications. Encryption as a concept prohibited except for corporations with security clearance and political connections.
- DoingIsLearning 1y agoThis is (mostly) about Tech companies' money, namely: - Palantir Technologies - 'not-for-profit' Thorn > The Commission’s failure to identify the list of experts as falling within the scope of the complainant’s public access request constitutes maladministration. [0] > ... the complainant contended that the precision rate of technologies like those developed by the organisation are often overestimated. It is therefore essential that any technical claims made by the organisation concerned are made public as this would facilitate the critical assessment of the proposal. [1] > The Commission presented a proposal on preventing and combating child sexual abuse, looking in particular at detecting child pornography. In this context, it has mentioned that support could be provided by the software of the controversial American company Palantir... [2] > Is Palantir’s failure to register on the Transparency Register compatible with the Commission’s transparency commitments? [2] (Palantir only entered the Transparency Registry in March 2025 despite being a multi million vendor for Europol and European Agencies for more than a decade) > No detailed records exist concerning a January meeting between European Commission President Ursula von der Leyen and the CEO of controversial US data analytics firm Palantir [3] > Kutcher and CEO Julie Cordua held several meetings with EU officials from 2020 to 2023 - before the former stepped down from his role - including European Commission President Ursula von der Leyen, Home Affairs Commissioner Ylva Johansson, and European Parliament President Roberta Metsola.[4] > The Ombudsman further concluded that Thorn had indeed influenced the legislative process of the CSAM regulation. “It is clear, for example, from the Commission’s impact assessment that the input provided by Thorn significantly informed the Commission’s decision-making. The public interest in disclosure is thus self-evident. [4] > EU Ombudsman Emily O’Reilly has announced that she has opened an investigation into the transfer of two former Europol officials to the chat control surveillance tech provider Thorn. [5] [0] https://www.ombudsman.europa.eu/en/decision/en/176658 https://www.ombudsman.europa.eu/en/decision/en/176658 [1] https://www.ombudsman.europa.eu/en/recommendation/en/179395 https://www.ombudsman.europa.eu/en/recommendation/en/179395 [2] https://www.europarl.europa.eu/doceo/document/E-9-2024-000165_EN.html https://www.europarl.europa.eu/doceo/document/E-9-2024-00016... [3] https://www.euractiv.com/news/commission-kept-no-records-on-davos-meeting-between-von-der-leyen-and-palantir-ceo/ https://www.euractiv.com/news/commission-kept-no-records-on-... [4] https://www.euronews.com/next/2024/07/18/european-ombudsman-slams-commission-for-secretive-approach-to-child-sexual-abuse-law https://www.euronews.com/next/2024/07/18/european-ombudsman-... [5] https://www.patrick-breyer.de/en/chat-control-eu-ombudsman-launches-investigation-into-europol/ https://www.patrick-breyer.de/en/chat-control-eu-ombudsman-l...
- randomNumber7 1y agoWhat would prevent me from writing my own program to do something simple like sending encrypted messages? Or just emails...
- giancarlostoro 1y agoGood luck being a DOD contractor overseas, wtf?
- __loam 1y agoGood luck having a bank account
- thewebguyd 1y agoThey'll push the scanning to the OS level, mandate that the OS does it. Hence the seemingly coordinated effort with Google on the sideloading changes, and enforcing play protect, etc. Like the TPM & Microsoft scare when TPM first started arriving in hardware, and we all thought it would be used to lock out other OSes. Only it's for real this time.
- randomNumber7 1y ago> They'll push the scanning to the OS level I don't know if this is possible so easily. Does the OS scan the memory of all applications? How does it know what is text and image data? What if it is encryped or even just obfuscated? Does the OS then track all changes of memory etc? Or you think it'll just have a rolling keylogger so you can't type in s.th. malicious?
- 1718627440 1y agoEverything a process does beyond touching memory is going through a syscall. The OS serves every key press to such a program.
- layer8 1y agoThe proposed regulation only applies to publicly available services, and only binds service providers, not end users. There is nothing preventing you from sending encrypted emails, just as there is nothing preventing you from pasting encrypted messages into WhatsApp or storing and sharing encrypted files in Dropbox.
- croes 1y agoI guess they don’t know you can encrypt files before you send them. They don’t even have to look like encrypted files.
- roywiggins 1y agoChat Control imagines your device being required to scan and report on all your plaintext.
- walterbell 1y agoEncrypted data can be input via analog device sensors.
- vessenes 1y agoThis was precisely some of the motivation behind pushing RCS onto Apple. The RCS spec has a termination point between providers -- a great spot to read some data for telecom providers and government agencies. Despite this, RCS is called "End to End" all the time. It's not. Use Signal or iMessage, depending on your security choices in iCloud.
- happyopossum 1y agoRCS is not called “end to end” by anyone - even Apple and Google explicitly state it’s not currently E2E encrypted. Apple has pledged to add e2ee to RCS on iPhones but they’re never claimed it’s that way today. They go out of their way to warn you it’s not the same level of security as iMessage.
- hn-ifs 1y agoOut of interest, what happens in the case of say an open source chat app developed outside the EU. Let's add that the developers are anonymous too, like truecrypt. What power does this legislation have then?
- layer8 1y agoApp stores that operate in the EU are subject to EU law, and can be forced to remove noncompliant apps.
- happyopossum 1y agoAhh, but they’ve already mandated side loading to piss off apple! Bit of an own-goal there.
- roywiggins 1y ago> Apps installed through alternative app distribution undergo a Notarization process to ensure every app meets baseline platform integrity standards... > Notarization for iOS and iPadOS apps is a baseline review that applies to all apps, regardless of their distribution channel, focused on platform policies for security and privacy and to maintain device integrity. https://support.apple.com/en-us/118110 https://support.apple.com/en-us/118110
- shuckles 1y agoWhy do you think the EU hasn’t opposed Apple’s plan to notarize every app, even sideloaded ones? They like the censorship potential.
- roywiggins 1y agoThey can just mandate it at the OS level. I don't know if the proposal envisions that already, but if it becomes popular surely that would come next.
- nisten 1y agoIf you are a smart kid in europe learn to vibecode XChacha20 & ed25519 encryption keys for you and your friends to chat with so you can go tell your incompetent government to go fuck themselves.
- i_am_a_squirrel 1y agobut then they'll make this a crime
- giancarlostoro 1y agoThen they're not encrypted apps.
- lovelearning 1y agoIs CSA really that widespread in Europe that everyone's chat messages have to be monitored? And if it is that widespread, shouldn't they try to address it socially to prevent CSA as much as possible rather than try to catch just the subset of tech-savvy abusers, that too after they've already committed CSA?
- quotemstr 1y agoEveryone in this debate understands that CSA is a pretext. Nothing is going to make any sense to you if you think ChatControl is an earnest and sincere to fight CSA in particular. The ultimate goal is for computers to run only authorized programs and to license and monitor development tools like the Soviets monitored typewriters.
- SamuelAdams 1y agoIt’s not about CSA, it’s about illegal content. And laws change all the time. For example, an individual can generate AI images of Hollywood actors using Stable Diffusion and a decently powerful computer. Said individual had the right to share those images online with a community. Now however the sharing and distribution of said images is considered illegal in my USA state. So, are the images said individual created and shared three years ago subject to prosecution? Even if the law went into effect 3 months ago?
- NoahZuniga 1y ago> Even if the law went into effect 3 months ago? No. The right not to be tried for actions that weren't crimes at the time is pretty universally applied in the west (I am not aware of the legal situation in other parts of the world, but I imagine it's honored there too). (Article 7 of the European Convention on Human Rights for the EU, Article I, Section 9 & 10 of the constitution for the US) > So, are the images said individual created and shared three years ago subject to prosecution? Generally, criminal acts are judged according to the rules of the jurisdiction where they happened, so I wouldn't be too worried about this. This isn't a universal rule though, so you won't find it enshrined in constitutions or treaties.
- 1y ago
- deleted 1y ago[deleted]
- lifestyleguru 1y agoThey'll push for it repeatedly until they succeed and then it will be irreversibile.
- sys32768 1y agoThey want the power to arrest you for your private thought crimes too.
- EasyMark 1y agoand keep them forever to use them against you in the future, if you become a "problem"
- rvz 1y agoSounds like a complete tyrannical dystopian hell hole to live in. But nevermind, We love the EU! /s
- EasyMark 1y agoMy answer to "think of the children" is "I am thinking of the children" * of their rights to privacy * their right to live in a democracy * the value of warrant based search vs nazi SS style * I want them to enjoy at -least- as much privacy as I currently enjoy * I don't want rando creeps reading their personal messages and keeping them forever, there's a reason memory fades, it lets us grow as people
- palata 1y agoTake it like this: your phone already "reads" absolutely everything you put on that phone. Apple or Google could do anything they want with that, but you trust them. You trust that they don't send everything that goes into your phone to their servers. ChatControl would run locally on your phone. It would compare the images that you receive/send to a list of illegal images, and if you happen to deal with one of them, it would report you. How is that destroying your democracy? Disclaimer: I am against ChatControl, but too many people seem to not understand what the problem with ChatControl is.
- Saline9515 1y agoBecause it's closed source so you have no idea of what is happening. You can then scan for other things, such as "hate speech", or "tax evasion" and then the slope becomes more slippery than a lube party on a vinyl sheet, and Kim Jong Un awaits you at the Ski Bar at the bottom. Those passive surveillance systems have a chilling effect on democracy, just like mandatory ID on social media, and provide politicians a lever so convenient that you know that it will be used, especially in the EU.
- palata 1y ago> Because it's closed source so you have no idea of what is happening. Exactly! That's the problem! It's not killing the encryption, it's not sharing all your communications with the government. Those are invalid arguments. The problem is that whoever controls the proprietary part of ChatControl (and that includes the list of illegal material) can abuse it to e.g. detect political opponents, or whatever they can imagine. I am just asking that we use the valid arguments against ChatControl. I read a lot of invalid arguments that won't help convincing politicians that it is a bad idea. They need to understand why it is a bad idea, the real reason.
- mnls 1y agoThe fact that EU politicians exclude themselves from the ChatControl is all you need to know about this.
- justapassenger 1y agoSource on that?
- bapak 1y agoFrom TFA > the proposed legislation includes exemptions for government accounts used for “national security purposes, maintaining law and order or military purposes”. Convenient.
- kevincox 1y agoI can buy the military exemption, and maybe some very top level government workers that are effectively military (example: POTUS). But the EU parliament has no reason to be excluded. It is definitely a terrible law if it is so bad that they won't pass it unless they are excluded.
- Vinnl 1y agoInterestingly Parliament is against Chat Control: https://edri.org/our-work/chat-control-what-is-actually-going-on/ https://edri.org/our-work/chat-control-what-is-actually-goin...
- pests 1y ago> top level government workers that are effectively military (example: POTUS) POTUS is very specifically NOT a member of the military. Elected civilian control was the whole point. Even Eisenhower had to (temporarily) give up his general rank to serve as president. I do understand your core point tho.
- 11mariom 1y ago> I can buy the military exemption While I understand it… there is no need for any exemption if the bad, stupid law will not be in place at all ;)
- meta-level 1y agoCan anyone explain to me what keeps anyone who doesn't want to be monitored from just sending PNGs (or similar) containing messages encrypted in each pixels LSBs? Doesn't all that just force everyone who has something to hide to use something else, less obvious?
- 1gn15 1y agoProbably friction. Will you be able to convince your friends to do that?
- meta-level 1y agoNo, probably not - but those bad guys with all their child porn and terrorist plans won't mind the friction (those will either encrypt or become EU politicians).
- palata 1y agoYou would be surprised. I mean, look at how many technically savvy people use Telegram and think it is "safe". Ever heard of top government officials mistakenly inviting a journalist in a group sharing top secret information?
- Stegomalware 1y ago[dead]
- Stegomalware 1y ago[dead]
- happyopossum 1y agoPresumably the distribution of an app that facilitates that would become illegal as well.
- hellojesus 1y ago
- apexalpha 1y agoUgh, I hate this but literally no one is paying attention. Its hard because everytime this gets defeated all the EUSSR people just wait a year and try again…
- gverrilla 1y agoThe USA wants this to remain a monopoly.
- josefritzishere 1y agoPrivacy for me and not for thee?
- netbioserror 1y agoUnenforceable tripe. Do not comply.
- varispeed 1y agoTo me this is simply an act of terrorism. People who are behind those proposals should be charged and face trial. There is no excuse for this and it is a stain on EU history for even letting this go so far. Anyone proposing this should not only be sacked but also referred to de-radicalisation / anti-terrorism programme in their country and forever banned from holding any kind of public sector office. There is no excuse.
- varispeed 1y agoWhy downvote? Because the terrorists wear suits, speak in committees, are mostly white, and there’s no blood on the floor (yet)? The method is different, but the aim is the same: intimidation and control of a population for political ends. If terrorism is defined as using violence or threats to intimidate a population for political or ideological ends, then “Chat Control” qualifies in substance. Violence doesn’t have to leave blood. Psychological and coercive violence is recognised in domestic law (see coercive control offences) and by the WHO. It causes measurable harm to bodies and minds. The aim is intimidation. The whole purpose is to make people too scared to speak freely. That is intimidation of a population, by design. It is ideological. The ideology is mass control - keeping people compliant by stripping them of private spaces to think, talk, and dissent. The only reason it’s not “terrorism” on paper is because states write definitions that exempt themselves. But in plain terms, the act is indistinguishable in effect from terrorism: deliberate fear, coercion, and the destruction of free will. You can argue legality if you like, but the substance matches the textbook definition.
- AlgebraFox 1y agoThis. ChatControl proposal is an act of terrorism. Doesn't matter it's done by those in power.
- bapak 1y agoWhere is Apple in all of this? They're such proponents of privacy that they've actively started encrypting as much as possible for decades but now that the EU is about to break all that they're silent. They raised such a fuss when the FBI asked to decrypt that single iPhone years ago, but now that millions are on the line... nothing?
- shuckles 1y agoWhen Apple attempted to anticipate these laws and propose a system which tried to navigate a compromise, the “pro-privacy” faction was so politically dumb they spread FUD about it and actively made sure no reasonable compromise could ever be reached. Now the public with reap what these advocates have sowed, good and hard. With regards to the FBI incident, Apple said at the beginning of their statement, “This moment calls for public discussion, and we want our customers and people around the country to understand what is at stake.” The EU is proposing a law. People assure me their laws are democratic and reflect the will of the people. Who is Apple to reject the outcome of public discussion? The FBI letter was written in a context where an agency was acting without the support of the public. That’s why the framing was all about misuse of the All Writs Act and lack of Congressional blessing for the requested power.
- chickenimprint 1y agoChatControl is exactly what Apple did. It's client-side, so no one is able to see your messages. The police sees if content hashes match known CSAM.
- shuckles 1y agoSee this is the type of hysterical flattening I was referring to. There is meaningful distinction in the details, such as Apple’s implementation being non-targetable, but if you think all client side scanning is the same you will concede everything.
- MaKey 1y agoWhat would you call a "reasonable compromise" between encryption and privacy?
- derelicta 1y agoI'm absolutely convinced now that anti-war stances will be soon included in the scope of this client side scanning. Peaceniks beware, citizens should crave war and dying for their elites.
- nikkwong 1y agoImagine a future where it becomes easier to commit terrorism because of some technological advancements—like smaller, less traceable bombs, or chemical weapons that are easily accessible and lead to higher casualties—like in the 1,000s or more. Imagine in that scenario, that the likelihood of you or someone you know becoming the victim of a terrorist attack is now non-trivial in your society. In a future where this becomes the norm, it would be interesting to see if individuals are more willing to adopt a level of increased surveillance as it seems like the only reasonable protection against terror. Right now this debate is oriented mostly around the fact that surveillance today is not a good deal—consumers give up their privacy and get nothing in return. But is there a tipping point? Technology draws us closer, day by day, and the threat matrix will become more sophisticated as time moves forward. Most individuals on HN are privacy absolutists but one should recognize that tradeoffs exist. That tradeoff is just not compelling today, but that doesn't mean that will always be the case. If you go to China, where everything and everyone is surveilled, I think you'd be surprised to find that many Chinese don't mind. They feel incredibly safe and don't have to worry about being victims of crimes, having their packages stolen, walking around late at night alone, etc. Walking around in China with absolute peace of mind around my own personal safety is a very eye-opening experience as someone coming from the US. I've always advocated for stringent privacy protections; but when giving that up buys you absolute safety in your immediate environment, that's not an experience you forget. I'm certainly not saying I'm a proponent of living in a surveillance state—I'm simply noting that tradeoffs exist and a sort of re-balancing is constantly occurring, which is just interesting to be aware of.
- KPGv2 1y ago> it would be interesting to see if individuals are more willing to adopt a level of increased surveillance as it seems as the only reasonable protection against terror. One presumes it would make terrorism easier if you could hack in and find out where your target is at any given time. What they're doing. What their plans are for this evening. Also I think one could probably point to the current US president as proof for why this is an insane idea. Imagine if he really did have access to everything we say.
- 1y ago
- htk 1y agoWhat a classic "Think of the children!" excuse for abuse.
- tomsmeding 1y agoI don't think ChatControl is a good idea. I also think that if you want to convince people of that, using the same misleading language tactics as the other side is not the way to go. > These scanning systems get it wrong most of the time. [...] Irish law enforcement confirms this: only 20.3% of 4,192 automated reports actually contained illegal material. Wrong most of the time that they report something. Technically correct, although a somewhat tricky formulation. Literally next paragraph: > Even with hypothetical 99% accuracy (which current systems don’t achieve), scanning billions of daily messages would generate millions of false accusations. This is a different accuracy percentage: here the author means 99% of all messages, not only the reported ones, which the previous 20.3% referred to. Furthermore, these two paragraphs together sound very fishy: if current systems are not accurate enough to generate "millions of false accusations", presumably (?) they generate at least that. But with the 20.3% true positives fraction, that would mean hundreds of thousands true accusations per day. Which part am I misunderstanding?
- dionian 1y agoDon't worry the governments would NEVER use this against you for political reasons later.
- baalimago 1y agoSo what if I host my own messaging service? As in: bring back IRC?
- aduwah 1y agoThe way I understand if your solution would become popular, the law can come after you to provide a log of messages in plain text. Also they will have the legal power to force the popular operating systems to enforce generic keylogging/packet capturing and whatnot.
- baalimago 1y agoI don't see how they can come after anyone who's using a specific protocol [0] by law. Expanding on this thought: if Chat Control passes, it will just be the death of social media as a chat platform. People will swap to something more rudimentary where it can't be enforced. Primary reason why being that it simply will be so much faster/more convenient than the apps which are forced to use chat control. The same reason as why streaming services are being ditched in favor of piracy will happen to social media. [0]: https://en.wikipedia.org/wiki/IRC https://en.wikipedia.org/wiki/IRC
- aduwah 1y agoYou think too much about the Regular Joes/Janes. No-one will care for more than 2 weeks apart from tech people
- xp84 1y agoFrom the article, the current flavor of "threat" this is being positioned to fight is CSAM. Does anyone believe that predators commit those heinous offenses because of the availability of encrypted channels to distribute those products of their crimes? I sure don't. The materials exist because of predators' access to children, which these surveillance measures won't solve. Best case scenario (and this is wildly optimistic) the offenders won't be able to find any 'safe' channels to distribute their materials to each other. The authorities really think every predator will just give up and stop abusing just because of that? What a joke. More likely of course, those criminals will just use decentralized tools that can't be suppressed or monitored, even as simple as plain old GPG and email. Therefore nothing of value will be gained from removing all privacy from all communication.
- anal_reactor 1y agoThat's not a bug, that's a feature. They'll say that current surveillance tools are insufficient, and demand more.
- dekken_ 1y agoAbsolutely, evidence of abuse is secondary to the actual abuse. Plus, the fact you could use/make AI/LLM/etc generate nefarious content that is hard to tell is fake, tells you the abuse isn't even what they are interested in.
- gjsman-1000 1y ago> Best case scenario (and this is wildly optimistic) the offenders won't be able to find any 'safe' channels to distribute their materials to each other. The theory is based on the documented fact that most crime is poorly thought through with terrible operational security. 41% is straight up opportunistic, spur of the moment, zero planning. It won't stop technologically savvy predators who plan things carefully; but that statistically is probably only a few percent of predators; so yes, it's probably pretty darn effective. There are no shortage of laws that are less effective that you probably don't want repealed - like how 40% of murderers and 75% of rapists get away with it. Sleep well tonight.
- 1y ago
- kleiba 1y agoThe is the n-th attempt to install some regulation that would (a) lead to increased surveillance of most of the population; and (b) is trivial to circumvent by those who the government is ostensibly trying to target. So clearly, the cost-benefit ratio is severely skewed for the EU population. Assuming that the regulators are fully aware of the above points, it's not very hard to speculate what the real intentions behind all of this are.
- stronglikedan 1y ago> The is the n-th attempt to install some regulation The sad part is that it would only take one attempt to codify the opposite into privacy laws as a basic right, should anyone ever bother to take up that gauntlet.
- elAhmo 1y agoOh, is this the infamous 'redacted list of attendees' when people inquired about who initially worked on this legislation/proposal? EU seems to be really good at some things, but this is an example of a legislation that can do way much harm than benefit.
- aborsy 1y agoAnyone one who does anything private or illegal will bypass that with tools that will be popular as a result. The government is left with scanning the data of the remaining 90% of population. They choose something sensitive as a pretext to push their agenda.
- aucisson_masque 1y agoWith Apple being able to forbid application on the App Store and Google now requiring developer to identify themselves before compiling app, and being able to block sideloading at any time, I don’t see what choice is left if you want to bypass that privacy invasion. I mean for the actual legit user. Pedophiles will still be able to use encrypted mail, Android phone that are not Google certified and so free to sideload anything, or even just passworded zip.
- chinathrow 1y agoThe EU should rather look at the issues at the eastern border these days.
- tdiff 1y agoI have a theory that everything that happens in regards of governmental control in China and Russia will eventually be copied in some form in western countries.
- tarwich 1y agoIsn't this the same regulatory body that enforced GDPR to supposedly provide citizens with more rights as to what happens to their data? Amusing.
- mywrathacademia 1y agoFirst they came for the Lockdown skeptics And I did not speak out Because I was not a Lockdown skeptic Then they came for the Social distancing skeptics And I did not speak out Because I was not a Social distancing skeptic Then they came for the Face mask skeptics And I did not speak out Because I was not a Face mask skeptic Then they came for the Vaccine skeptics And I did not speak out Because I was not a Vaccine Skeptic Then they came for the Vaccine passport skeptics And I did not speak out Because I was not a Vaccine passport skeptic Then they came for me And there was no one left To speak out for me
- niels8472 1y agoAh, so we will fight child porn by detecting family pics of children in the shower (or w/e) and sending them off to a "trusted" 3rd party who will no doubt leak them at some point. Also, if I were a pedophile I know where I'd send my resume...
- pona-a 1y agoThe number of people in these threads defending involuntary bugging of every phone because you can devil-advocate it maybe might actually save the children is insane for a forum called Hacker News. Either the contrarian population has been getting out of hand, or we have truly lost our minds and stand to lose what remains of our civil liberties.
- deleted 1y ago[deleted]
- txrx0000 1y agoDear citizens of the EU: If this gets pushed through, you will gradually lose control of your government much like how the people of the UK already lost control of theirs. What are you going to do when the government's interests inevitably drift out of alignment with yours? Start a political movement? You will have the police knocking on your door for criticizing the establishment. Start a revolution? You have no weapons. You can't even organize a resistance because all channels of communication are monitored. You have neither the pen nor the sword. There is no longer an incentive for the government to serve you, and so it eventually won't. No amount of protest will recover the freedom you once had. You're heading towards a society where everyone feels oppressed but no one can do anything about it.
- bigyabai 1y agoDear citizens of the US: Please stop funding, allying with and protecting the manufacturers of surveillance tools. Stop exporting Palantir products and importing privacy-destroying devices from businesses like Greyshift and Cellebrite. Insist that the US government stop shielding hackers-for-hire like NSO Group who indiscriminately lease their products for discriminatory and illegal purposes. Stop defending "OEM" control that we have all known is a stand-in for federal steering since the Snowden leaks. Stop marketing E2EE while backdooring server and client hardware for "emergency" purposes. Do that, and you'll never be accused of hypocrisy again. Signed, a US citizen.
- theodric 1y agoCollective guilt projection is incredibly unfair. What is the average US citizen expected to do in this? I hereby promise not to buy any weapons systems from Palantir or use Cellebrite if I forget my phone's PIN code. Am I one of the good ones now?
- bigyabai 1y agoMy point is to highlight the hypocrisy in HN casting stones from a glass house. I don't really believe you're beholden to fixing it (as I said, I'm a US citizen too). We just have to accept that the United States started this and is the only nation on Earth that can stop it. American surveillance technology is the role-model for abusive regimes and perfectly sensible governments around the world.
- nickslaughter02 1y agoI think many outside of EU dismiss this as an EU only thing and don't think much about it. 1. Have you ever texted someone from EU? You are now chat controlled too. 2. EU is pumping billions to foreign countries to promote EU values. How long until they condition this "help" with chat control?
- palata 1y agoMost arguments I see against ChatControl sound like bullshit to me. How do we expect to convince anyone to go against ChatControl with those? I feel unease when it comes to ChatControl; I don't want my devices to run proprietary, opaque algorithms on all my data. And it feels like it fundamentally has to be opaque: nobody can't publish an open source list of illegal material together with their hash (precisely because it is illegal). That is why I don't want ChatControl: I would want someone to formally prove that it cannot be abused, just because of what it means. The classic example being: what happens if someone in power decides to use this system to track their opponents? But most comments and most articles talk about anything but that, with honestly weird, unsupported claims: > It's the end of encryption How so? What appears on my screen is not encrypted and will never be encrypted, because I need to read it. We all decrypt our messages to read them, and we all write them unencrypted before we send them. > It won't fight CSAM Who are you kidding? Of course it will. It will not solve the problem entirely, but it will be pretty damn efficient at detecting CSAM when CSAM is present in the data being scanned. > With ChatControl, every message gets automatically checked, assuming everyone is guilty until proven innocent and effectively reversing the presumption of innocence. When you board a plane, you're searched. When you enter a concert hall, you're search. Nobody would say "you should let me board the plane with whatever I put in my bag, because I'm presumed innocent". > While your messages still get encrypted during transmission, the system defeats the purpose of end-to-end encryption by examining your content before it gets encrypted. Before it gets encrypted, it is not encrypted. So the system is not breaking the encryption. If (and that's a big if) this system was open source, such that anyone could check what code it is running and prove that the system is not being abused, then it would be perfectly fine. The problem is that we cannot know what the system does. But that's a different point (and one of the only valid arguments against ChatControl). > Proton point out this approach might be worse than encryption backdoors. Backdoors give authorities access to communications you share with others. This system examines everything on your device, whether you share it or not. How is it worse? Backdoors give access to communications, this system (on the paper) does not. This system is better, unless we admit that we can't easily audit what the system is doing exactly. Which again is the one valid argument against ChatControl. > The regulation also pushes for mandatory age verification systems. No viable, privacy-respecting age verification technology currently exists. These systems would eliminate online anonymity, requiring users to prove their identity to access digital services. This is plain wrong. There are ways to do age verification anonymously, period. > Police resources would be overwhelmed investigating innocent families sharing vacation photos while real crimes go uninvestigated. How to say you don't know how the police works without saying you don't know how the police works? Anyway, that's the problem of the police. > Google’s algorithms flagged this legitimate medical consultation as potential abuse, permanently closed his account and refused all appeals. The problem is the closing and refusing of appeals. > The letter emphasizes that client-side scanning cannot distinguish between legal and illegal content without fundamentally breaking encryption and creating vulnerabilities that malicious actors can exploit. Then explain how? How is it fundamentally breaking encryption and creating vulnerabilities? Stop using bad arguments. If you have actual reasons to go against ChatControl, talk about those. You won't win with the bullshit, invalid arguments. > ChatControl catches only amateur criminals who directly attach problematic content to messages. Yep, that's an argument in favour of ChatControl: it does catch some criminals. How many criminals are professionals? Do you want to make it legal to be an amateur criminal? Don't get me wrong: I am against ChatControl. Because of one argument I believe to be valid: we fundamentally cannot know what the algorithm doing the scanning is doing, so those who control it could abuse it. Of all the discussions I have seen against ChatControl, I haven't seen another valid argument. But this one is enough. Stop saying bullshit, start using the valid arguments. And maybe politicians will hear them.
- alkonaut 1y agoThis must be one of the least popular pieces of regulation ever.
- deleted 1y ago[deleted]
- zkmon 1y agoA nation is a concept that comes into existence only because people agree to lose some of their freedom, income and privacy. To what extent is the question. 100& privacy is not possible and it simply derails a nation, due to lack visibility and lack of control.
- Saline9515 1y agoIndeed, the world was a chaotic place before the soviets invented CCTV and allowed therefore the creation of civilization.
- JohnLocke4 1y agoInterview from DR (Danish public news broadcast) with the Danish judicial minister Peter Hummelgaard, the politician who conceived the proposal: https://www-dr-dk.translate.goog/nyheder/viden/teknologi/analyse-derfor-holder-hummelgaards-udsagn-om-kryptering-ikke?_x_tr_sl=zh-TW&_x_tr_tl=en&_x_tr_hl=en-US&_x_tr_pto=wapp&_x_tr_hist=true https://www-dr-dk.translate.goog/nyheder/viden/teknologi/ana... It is very obvious that he doesn't understand e2e, yet he will not listen. Bro couldn't even read the Wikipedia page
- jjcm 1y agoThe one thing that I never see answered in the proposals is a simple answer to, "what's stopping CSAM users from using open-source encryption?". You can ban this at a provider scale, but you simply can't track or enforce custom implementations at a small scale.
- blaze33 1y agoI regularly see similar articles with similar comments here, but there's one thing I still don't understand: From the European Convention on Human Rights[1]: ARTICLE 8 Right to respect for private and family life 1. Everyone has the right to respect for his private and family life, his home and his correspondence. 2. There shall be no interference by a public authority with the exercise of this right except such as is in accordance with the law and is necessary in a democratic society in the interests of national security, public safety or the economic well-being of the country, for the prevention of disorder or crime, for the protection of health or morals, or for the protection of the rights and freedoms of others. So I wonder, what is the legal argument solid enough to justify interfering with everybody's right to privacy? My layman understanding of the usual process is like, we want surveillance over those people and if it seems reasonable a judge might say ok but for a limited time. Watching everyone's communications also seems at odds with the principle of proportionality[2]. [1]https://www.echr.coe.int/documents/d/echr/Convention_ENG https://www.echr.coe.int/documents/d/echr/Convention_ENG [2]https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:12016M005 https://eur-lex.europa.eu/legal-content/EN/TXT/?uri=CELEX:12...
- palata 1y ago> what is the legal argument solid enough to justify interfering with everybody's right to privacy? "... except such as is in accordance with the law" And the "interfering" coming from ChatControl is that "some algorithm" locally scans and detects illegal material, and doesn't do anything if there is no illegal material. > Watching everyone's communications also seems at odds with the principle of proportionality It's a bit delicate here because one can argue it's not "watching everyone's communications". The scanning is done locally. Nobody would say that your OS is "watching your communications", right? Even though the OS has to "read" your messages in order to print them on your screen. Note that I am against ChatControl. My problem with it is that the list of illegal material (or the "weights" of the model deciding what is illegal) cannot be audited easily (it won't be published as it is illegal material) and can be abused by whoever has control over it.
- pests 1y ago
- NaQeeLPK 1y agoWhich political parties in which countries should one vote for? It's a good campaign, but let's say national elections are coming, one should know which politicians are in favour or against. How else can we let our opinion be known other than by voting for the right politicians?
- oddb0d 1y agoJust remove the middleman & use https://theweave.social/moss/ https://theweave.social/moss/ p2p f/loss groupware
- BrandoElFollito 1y agoAfter reading the article I do not understand how this is supposed to work. The author says that "the system" will scan data. What "system"? Android? Windows? Linux? If system means "an application" - how would it come to my OS? Pre-installed? By whom? On Linux??
- vfclists 1y agoThe solution is to use something like PGP but for chat. Everyone owns their key and uses it to exchange their info with others. Its not complicated and has existed for ages. Simple fact is people should learn more about IT and exercise more control over their affairs instead of handing it over to corporations.
- rickcarlino 1y agoDoes the EU have established precedent to allow mass scanning of snail mail?
- siilats 1y agoI mean USA just went through this when Trump team all got FISA-d and tracked. Chat control is bunch of sha hashes that match. You can basically figure out everyone who has Trump in their WhatsApp contacts and then get every message that matches Trump and no one can tell because it searches for sha(trump) not Trump. It’s perfect tool for surveillance state
- pickledonions49 1y agoNewer versions or IRC utilize SSL/TLS on port 6697. I would download copies of open source client/server software (certificates can be self-signed). A Raspberry Pi can host a small chat server.
- evanjrowley 1y agoI don't like this, but to be fair, Europe's history has been very bloody. It's a continent that knows all too well what the consequences are for radicalization. With the recent suspicious deaths of several AfD political leaders in Germany, it seems that the political fight is being fiercely fought today. Could this be what ChatControl is really about?
- 1vuio0pswjnm7 1y agoIs this the latest draft https://data.consilium.europa.eu/doc/document/ST-10131-2025-INIT/en/pd https://data.consilium.europa.eu/doc/document/ST-10131-2025-... This legislation appears to be aimed at "services" offered to the general public that provide encrypted messaging, particularly the facility to share URLs, images and video This proposed legislation does not appear to contemplate internet service providers as encrypted chat/messaging service providers It stands to reason that internet subscribers who do not use encrypted chat services offered to the public by third party intermediaries, aka middlemen, would not be affected by this legislation The legislation imposes an obligation on encrypted chat service providers, i.e., non-parties to the communication, to scan _someone else's_ private messages Obviously, this obligation to scan someone else's messages would not apply to internet subscribers communicating with each other peer-to-peer, i.e. it would not apply to the parties to the communication It is interesting how HN commenters seem to assume that if this legislation were enacted, Europeans would continue to use these third party services, e.g., for planning the next revolution (the top comment is hilarious) The legislation is only targeting "Big Tech" and wannabe Big Tech "platforms", it is not targeting encryption per se.^1 It is targeting _those companies'_ use of encryption 1. Law enforcement use of encryption is explicitly excluded It was never a good idea to let "Big Tech" intermediate communication over the internet. These companies are not a source of "privacy". Their "business model" is based on mass surveillance. As mass surveillance data collectors, "Big Tech" is an alluring and easy target for any government, a "one-stop shop" for law enforcement. There is less need for government surveillance when "Big Tech" is doing it for them
- deleted 1y ago[deleted]
- storus 1y agoThis push feels like preparation for a war, and subsequent total control of communication. Nobody hopefully believes it's about children.
- cbar_tx 1y agoVery liberal.
- daft_pink 1y agoNext they’re going to tell us it’s to prevent csam.
- CHB0403085482 1y agoWanting exemptions for government staff screams "rules for thee but not for me". sigh
- 11mariom 1y agoThe sad part - we have to win every time. And they'll try again and again… And one win of gov side is enough… And the worst part - EU is so democratic that we even do not elect most of the people.
- elric 1y agoIf the goal really was "to protect the children" then all the time, money, and effort being spent on this dystopian shit would instead be spent on the treatment of pedosexuals in order to reduce the number of perpetrators. On child support and on reducing poverty in order to reduce the number of victims under the radar. On psychological support for the victims of sexual crimes. On reinforcing justice systems so they can process the existing cases related to (child) sexual assault. Etc.
- senko 1y agoMeanwhile, in one part of the EU (Croatia): urgent tax law change is being considered to allow the tax authorities to demand access (passwords, keys, etc) to any electronic/digital device or service used by a person involved with (owning, operating, or just working in) a business, "to combat tax fraud". No warrants necessary.
- onequestion1 1y agoCan you please give a source on this? t. balkanian
- senko 1y agohttps://www.index.hr/mobile/vijesti/clanak/porezna-ce-uskoro-moci-traziti-sifre-od-ljudi-pitali-smo-ih-sto-ce-im/2713403.aspx https://www.index.hr/mobile/vijesti/clanak/porezna-ce-uskoro...
- otrack 1y agoThe situation is less dramatic than this article says. https://edri.org/our-work/chat-control-what-is-actually-going-on/ https://edri.org/our-work/chat-control-what-is-actually-goin...
- sjw987 1y agoIt's extraordinary that this style of governance keeps coming around. We judged this sort of behaviour from countless other countries in the past. At the end of the day, everybody ends up wanting more control.
- silverliver 1y agoI'll just repost what I posted in the last thread: > There is no on-device scanning without compromising privacy. Scanning that can detect child abuse can also detect human rights activists, investigative journalists, and so on. I imagine this technology can be easily used by the government to identify journalists by scanning for material related to their investigation. > On-device scanning is a fabrication that Apple foolishly introduced to the mainstream, and one that rabid politicians bit into and refuse to let go. And I'll add this: Citizens lose of their right to privacy is the death of their democracy.
- sharpshadow 1y agoWhat is not clear to me is what happens if one has pictures and communication of highly illegal stuff which is not csam.
- spike__ 1y agoAt this point just drop the pretense and stop calling yourself a democracy when people have no say in this shit.
- selinkocalar 1y agoThis is going to break so many things. End-to-end encryption either works or it doesn't. There's no middle ground where you can scan messages but keep them 'private.' Compliance overhead alone will kill a bunch of smaller messaging apps that can't afford all the regulatory stuff.